9.3

CVSS4.0

CVE-2025-34082 - IGEL OS Secure Terminal and Secure Shadow Remote Code Execution

A command injection vulnerability exists in IGEL OS versions prior to 11.04.270 within the Secure Terminal and Secure Shadow services. The flaw arises due to improper input sanitization in the handling of specially crafted PROXYCMD commands on TCP ports 30022 and 5900. An unauthenticated attacker w…

πŸ“… Published: July 3, 2025, 7:46 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS4.0

CVE-2025-34086 - Bolt CMS Authenticated Remote Code Execution via Profile Injection and File Rename

Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achieve remote code execution. A user with valid credentials can inject arbitrary PHP code into the displayname field of the user profile, which is rendered unsanitized in backend tem…

πŸ“… Published: July 3, 2025, 7:46 p.m. πŸ”„ Last Modified: April 7, 2026, 2:09 p.m.

9.3

CVSS4.0

CVE-2025-34061 - PHPStudy 2016-2018 Backdoor Remote Code Execution Vulnerability

A backdoor in PHPStudy versions 2016 through 2018 allows unauthenticated remote attackers to execute arbitrary PHP code on affected installations. The backdoor listens for base64-encoded PHP payloads in the Accept-Charset HTTP header of incoming requests, decodes and executes the payload without pr…

πŸ“… Published: July 3, 2025, 7:46 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2025-53370 - Citizen stored XSS vulnerability through short descriptions

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, short descriptions set via the ShortDescription extension are inserted as raw HTML by the Citizen skin, allowing any user to insert arbitrary HTML into the DOM by editing a page. …

πŸ“… Published: July 3, 2025, 7:45 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 2:19 p.m.

8.6

CVSS3.1

CVE-2025-53368 - Citizen is vulnerable to stored XSS attack in the legacy search bar

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, page descriptions are inserted into raw HTML without proper sanitization by the Citizen skin when using the old search bar. Any user with page editing privileges can insert cross-…

πŸ“… Published: July 3, 2025, 7:34 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 2:20 p.m.

9.1

CVSS3.1

CVE-2025-23968 - WordPress AiBud WP plugin <= 1.9 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in WebFactory AiBud WP aibuddy-openai-chatgpt allows Upload a Web Shell to a Web Server.This issue affects AiBud WP: from n/a through <= 1.9.

πŸ“… Published: July 3, 2025, 6:49 p.m. πŸ”„ Last Modified: April 23, 2026, 3:24 p.m.

6.3

CVSS4.0

CVE-2025-6071 - Hard Coded Key used for AES encryption

Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. An attacker can gain access to salted information to decrypt MQTT information. This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016.

πŸ“… Published: July 3, 2025, 4:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS4.0

CVE-2025-6072 - Stack Buffer Overflow in MQTTCore

Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to the control network, and CVE-2025-6074 is exploited, the attacker can use the JSON configuration to overflow the date of expiration field.Th…

πŸ“… Published: July 3, 2025, 4:53 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS4.0

CVE-2025-6073 - Stack Buffer Overflow in MQTTCore

Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to the control network, and user/password broker authentication is enabled, and CVE-2025-6074 is exploited, the attacker can overflow the buffer …

πŸ“… Published: July 3, 2025, 4:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2025-6074 - Authentication Bypass to the MQTT configuration Web Interface

Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to source code and control network, the attacker can bypass the REST interface authentication and gain access to MQTT configuration dat…

πŸ“… Published: July 3, 2025, 4:46 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4800 of 34,919
Β« previous page Β» next page
Filters